Vulnerability Name: | CVE-2006-0486 (CCN-38513) | ||||||||
Assigned: | 2006-01-25 | ||||||||
Published: | 2006-01-25 | ||||||||
Updated: | 2017-10-11 | ||||||||
Summary: | Certain Cisco IOS releases in 12.2S based trains with maintenance release number 25 and later, 12.3T based trains, and 12.4 based trains reuse a Tcl Shell process across login sessions of different local users on the same terminal if the first user does not use tclquit before exiting, which may cause subsequent local users to execute unintended commands or bypass AAA command authorization checks, aka Bug ID CSCef77770. | ||||||||
CVSS v3 Severity: | 5.9 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||
CVSS v2 Severity: | 4.6 Medium (CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P) 3.4 Low (Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
3.4 Low (CCN Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Bypass Security | ||||||||
References: | Source: MITRE Type: CNA CVE-2006-0486 Source: CCN Type: SA18613 Cisco IOS AAA Command Authentication Bypass Vulnerability Source: SECUNIA Type: UNKNOWN 18613 Source: CCN Type: SECTRACK ID: 1015543 Cisco IOS AAA Command Authorization Feature May Let Remote Authenticated Users Gain Elevated Privileges Source: SECTRACK Type: UNKNOWN 1015543 Source: CISCO Type: Vendor Advisory 20060125 Response to AAA Command Authorization by-pass Source: CCN Type: cisco-sr-20060125-aaatcl Cisco Security Response: AAA Command Authorization by-pass Source: OSVDB Type: UNKNOWN 22723 Source: CCN Type: OSVDB ID: 22723 Cisco IOS tclsh Login Process Re-Use Source: XF Type: UNKNOWN cisco-aaa-tcl-auth-bypass(24308) Source: XF Type: UNKNOWN cisco-aaa-tclquit-auth-bypass(38513) Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:4905 | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
Oval Definitions | |||||||||
| |||||||||
BACK |